US10365840B2ActiveUtilityA1

System and method for providing a secure airborne network-attached storage node

Assignee: BOEING COPriority: Jun 30, 2017Filed: Jun 30, 2017Granted: Jul 30, 2019
Est. expiryJun 30, 2037(~10.9 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/1408H04B 1/40H04B 1/3818G08B 13/1409G06F 21/88G06F 21/554G06F 13/4081G06F 13/1668G06F 12/0246G06F 21/31G06F 3/0683G06F 3/0622
36
PatentIndex Score
0
Cited by
11
References
20
Claims

Abstract

A network-attached storage system and method includes a network-attached storage apparatus and removable storage medium installed in sockets in that apparatus. The storage medium includes an RF receiver and circuitry for erasing or disabling access to memory thereon. A host controller determines when a removable storage medium has been installed in or removed from a socket. A network interface controller is provided for coupling to an external network. An RF transmitter is coupled to a controller. The controller is coupled to each socket via the host controller and to the network interface controller. The controller determines, based on signals from the host controller, when the removal of a removable storage medium from the socket is unauthorized and sends a signal to the RF transmitter for transmission to the RF receiver in the removed removable storage medium to cause the memory therein to be erased or access thereto to be disabled.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A system comprising:
 a storage medium including:
 a radio-frequency (RF) receiver; 
 a memory configured to store data; and 
 access circuitry configured to make the data inaccessible upon receipt of a particular signal via the RF receiver; and 
 
 a memory reader comprising:
 a socket configured to receive the storage medium; 
 a host controller coupled to the socket, wherein the host controller is configured to determine whether the storage medium has been installed in or removed from the socket; 
 a network interface controller configured to couple to an external network; 
 an RF transmitter; and 
 a controller coupled to the socket via the host controller, the controller coupled to the network interface controller, the controller configured to, in response to commands received from the network interface controller, access the data while the storage medium is installed in the socket, the controller configured to provide responses via the network interface controller based on the data, wherein the controller is configured to receive an indication from the host controller indicating that the storage medium has been has been installed in or removed from the socket, wherein the controller is configured to, responsive to the storage medium being removed, determine whether removal of the storage medium was authorized, and wherein the controller is configured to, responsive to removal of the storage medium being unauthorized, send the particular signal to the RF transmitter for transmission to the RF receiver to cause the access circuitry to make the data inaccessible. 
 
 
     
     
       2. The system of  claim 1 , wherein the storage medium includes a memory card. 
     
     
       3. The system of  claim 2 , wherein the memory card includes a Secure Digital (SD) card. 
     
     
       4. The system of  claim 3 , wherein the host controller includes an SD card host controller. 
     
     
       5. The system of  claim 1 , wherein the memory reader further includes a keypad coupled to the controller, and wherein the controller determines that removal of the storage medium from the socket was unauthorized in response to the storage medium being removed from the socket without entry of a particular security code on the keypad. 
     
     
       6. The system of  claim 1 , wherein the memory reader further includes:
 a keypad coupled to the controller; 
 an access door configured to cover the socket and the storage medium while the access door is in a first position, wherein the access door is configured to provide access to the socket and the storage medium while the access door is in a second position; 
 a sensor coupled to the controller, the sensor configured to determine whether the access door is in the second position, wherein removal of the storage medium is unauthorized responsive to the storage medium being removed after the access door is moved to the second position from the first position without entry of a particular security code on the keypad. 
 
     
     
       7. The system of  claim 1 , wherein the memory reader further includes a keypad coupled to the controller, wherein the controller is configured to securely erase the data responsive to entry of an incorrect security code on the keypad a particular number of times. 
     
     
       8. The system of  claim 1 , wherein the access circuitry is configured to make the data inaccessible by disabling access to the memory. 
     
     
       9. The system of  claim 1 , wherein the access circuitry is configured to make the data inaccessible by deleting the data. 
     
     
       10. A system comprising:
 a storage medium including:
 a radio-frequency (RF) receiver; 
 a memory configured to store data; and 
 access circuitry configured to make the data inaccessible upon receipt of a particular signal via the RF receiver; and 
 
 a memory reader comprising:
 a plurality of sockets, wherein a first socket of the plurality of sockets is configured to receive the storage medium; 
 a host controller coupled to each socket of the plurality of sockets, wherein the host controller is configured to determine whether the storage medium has been installed in or removed from the first socket; 
 a network interface controller configured to couple to an external network; 
 an RF transmitter; and 
 a controller coupled to each socket of the plurality of sockets via the host controller, the controller coupled to the network interface controller, the controller configured to, in response to commands received from the network interface controller, access the data while the storage medium is installed in the socket, the controller configured to provide responses via the network interface controller based on the data, wherein the controller is configured to receive an indication the host controller indicating that the storage medium has been has been installed in or removed from the first socket, wherein the controller is configured to, responsive to the storage medium being removed, determine whether removal of the storage medium was authorized, and wherein and the controller is configured to, responsive to removal of the storage medium being unauthorized, send the particular signal to the RF transmitter for transmission to the RF receiver to cause the access circuitry to make the data inaccessible. 
 
 
     
     
       11. The system of  claim 10 , wherein the storage medium includes a USB flash drive. 
     
     
       12. The system of  claim 11 , wherein the host controller includes a USB hub. 
     
     
       13. The system of  claim 10 , wherein the memory reader further includes a keypad coupled to the controller, and wherein the controller determines that removal of the storage medium from the socket was unauthorized in response to the storage medium being removed from the socket without entry of a particular security code on the keypad. 
     
     
       14. The system of  claim 10 , wherein the memory reader further includes:
 a keypad coupled to the controller; 
 an access door configured to cover the socket and the storage medium while the access door is in a first position, wherein the access door is configured to provide access to the socket and the storage medium while the access door is in a second position; 
 a sensor coupled to the controller, the sensor configured to determine whether the access door is in the second position, wherein removal of the storage medium is unauthorized responsive to the storage medium being removed after the access door is moved to the second position from the first position without entry of a particular security code on the keypad. 
 
     
     
       15. The system of  claim 10 , wherein the memory reader further includes a keypad coupled to the controller, wherein the controller is configured to securely erase the data responsive to entry of an incorrect security code on the keypad a particular number of times. 
     
     
       16. The system of  claim 10 , wherein the memory reader further includes a display coupled to the controller, wherein the display is configured to provide status information to a user. 
     
     
       17. The system of  claim 10 , wherein the memory reader further includes a display coupled to the controller, wherein the display is configured to provide command information to a user. 
     
     
       18. A method comprising:
 accessing data stored in a memory of a storage medium based on commands received from a network interface controller of a memory reader, the storage medium installed in a socket of the memory reader; 
 detecting removal of the storage medium from the socket; 
 determining whether removal of the storage medium from the socket was authorized; 
 in response to removal of the storage medium being unauthorized, generating a particular signal; and 
 initiating transmission of the particular signal to the storage medium, wherein receiving the particular signal causes access circuitry of the storage medium to make the data inaccessible. 
 
     
     
       19. The method of  claim 18 , wherein the determination that removal of the storage medium from the socket was unauthorized is in response to the storage medium being removed from the socket without entry of a particular security code on a keypad coupled to the memory reader. 
     
     
       20. The method of  claim 18 , wherein removal of the storage medium is unauthorized responsive to the storage medium being removed after an access door associated with the socket is opened without entry of a particular security code on a keypad coupled to the memory reader.

Join the waitlist — get patent alerts

Track US10365840B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.